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Abstract 



o 
o 

We propose a new scheme for quantum secret sharing (QSS) that uses a modulated high-dimensional time-bin 

> ' 

' entanglement. By modulating the relative phase randomly by {0, tt}, a sender with the entanglement source can 
randomly change the sign of the correlation of the measurement outcomes obtained by two distant recipients. 



The two recipients must cooperate if they are to obtain the sign of the correlation, which is used as a secret 



' key. We show that our scheme is secure against intercept- and-resend (I-R) and beam splitting attacks by an 
outside eavesdropper thanks to the non-orthogonality of high-dimensional time-bin entangled states. We also 
show that a cheating attempt based on an I-R attack by one of the recipients can be detected by changing the 
dimension of the time bin entanglement randomly and inserting two "vacant" slots between the packets. Then, 
cheating attempts can be detected by monitoring the count rate in the vacant slots. The proposed scheme has 
better experimental feasibility than previously proposed entanglement-based QSS schemes. 
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1 Introduction 

Many quantum information systems including quantum cryptography and quantum computer have been in- 
tensively studied in recent years Of these, quantum secret sharing (QSS) has been attracting attention 
[HEIEEIEIEIIHIEI- The basic idea of secret sharing is that a secret key transmitted by a sender is shared 
between two or more recipients in such a way that the key can be reconstructed only if all recipients collaborate. 
The purpose of QSS is to provide this function with absolute security using quantum mechanics : a secret key 
from a sender is transmitted over a quantum channel to two (or more) recipients, and the key is used to encrypt 
communication between the sender and the recipients in a classical channel that cannot be modified but may 
be overheard by an eavesdropper. 

The first QSS scheme proposed by Hillery et al. used a three-particle entangled Greenberger-Horne-Zeilinger 
(GHZ) state Although this scheme elegantly showed the essence of QSS, it is hard to realize experimentally 
because of the inefficiency as regards the generation of a three-particle entangled state ^Ul- Several variations 
and theoretical expansions of QSS have been reported since the publication of this pioneering work 001012113 
IHl E] . Among them, schemes based on two-particle entangled states seem to have good experimental feasibility 
with optical setups [32]. These schemes use four non-orthogonal Bell states and two measurement bases that 
are non-orthogonal to each other to prevent an eavesdropper from obtaining the key without inducing errors. 
Therefore, the experimental configurations are complex and difficult to implement. Recently, simpler schemes 
have been proposed based on sequential communication of a sing le qubit |H||n|. In a sense, these methods insert 
some users who undertake unitary transformation into a transmission line of quantum key distribution (QKD) 
systems using single photons. Therefore, the secure key distribution distances of these methods are expected 
to be similar to those of QKD systems using single photons. In an analogy with the relationship between the 
secure key distribution distance of a single-photon-based QKD and that of an entanglement-based QKD, the 
secure key distribution distance of these QSS schemes will be smaller than those of entanglement-based QSS 
schemes. 

In this paper, we propose a new QSS scheme based on a two-photon entangled state. Our approach employs 
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high-dimensional time-bin entanglement [111 112) . which is an expansion of time- bin entanglement with two 
time slots ^3]- We apply a differential phase modulation to high-dimensional time-bin entanglement. We 
show that our scheme is secure against an intercept-and-resend (I-R) attack or a beam splitting (BS) attack, 
because an eavesdropper cannot reconstruct the whole wavefunction of the modulated high-dimensional time- 
bin entanglement by such attacks. In other words, our scheme utilizes the non-orthogonality of modulated 
high-dimensional entangled states to ensure that an eavesdropper cannot determine the state with a single 
measurement, instead of using four non-orthogonal Bell states as in jJJ 1^. In addition, the dimensions of 
the time-bin entangled states are randomly changed packet by packet, and two vacant time slots are inserted 
between packets. As a result, cheating attempts based on an I-R attack by one of the recipients can be detected 
by monitoring the count rate of the vacant slots. Note that our security analysis is based on specific attacks, and 
a full security analysis to prove unconditional security is beyond the scope of this paper. The source of a high- 
dimensional entangled state is easier to construct than the sources of previous entanglement-based QSS schemes. 
In addition, the recipients of our scheme do not have to select one from two non-orthogonal measurement bases. 
These characteristics make the configuration very simple and the presented scheme experimentally feasible. 

The structure of this paper is as follows. An overview of the proposed scheme is provided in Sec. 2. In 
sections 3 and 4, we discuss security against eavesdropping by an outsider and cheating attempts by one of the 
recipients, respectively. In section 5 we discuss the obtained results, and describe a possible modification of the 
proposed protocol. We conclude the paper in Sec. 6. 

2 Proposed scheme 

Figure ^ shows the configuration of our proposed scheme, which is based on a simple Franson interferometer 
setup m. Charlie generates packets of high-dimensional time-bin entangled states spanned by N time slots, 
each of which is followed by two vacant time slots. The state of a packet (with the following vacant slots) is 
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Figure 1: Schematic of the proposed QSS system. 

expressed as 

1 ^ 

I*) = ^ Ve^*Mfc)s|fc).+0- |7V+l),|7V+l),: + 0- |iV + 2),,|iV + 2)„ (1) 
fe=i 

where the expression \k)x represents a state in which there is a photon in the fcth time slot in a mode x, signal 
(s) or idler (z). is the phase at the kth time slot and is modulated randomly by {0,7r}. The dimension N 
is randomly changed packet by packet. The signal and idler photons are separated and sent to Alice and Bob, 
respectively. Alice and Bob put the photons into 1-bit delayed interferometers whose two outputs are connected 
to photon counters. A state \k)s is converted as follows by a 1-bit delayed interferometer. 

^ i (|fc, a), - |fc, 6), + |/c + 1, a), + \k + l, b)^) (2) 

In the expression \k,y)x, k shows the time slot where there is a photon, y is the output port (a or b) of the 
delayed interferometer, and x denotes signal (s) or idler (s). By plugging Eq. into Eq. we can obtain 
the state at the output of the interferometers, which is shown by 

^ PMl,a).|l,a).-e*|l,a),|l,6),-e**i|l,5),|l,a),-He'^i|l,6),|l,5), 
4VA^ 

N 

+ {(e'^'"' + e'^''}\k, a)s\k, a), + {e'^"-' - e'^'')\k, a)s\k, b), 

k=2 

^{e"^<^-^ -e"^^)\k^b),\k,a), + {e''^''-^ +e"^'')\k,b),\k,b)i} 
+e'"'>« \N + l,a),\N -f I, a), + e'"^" |iV + 1, a)s\N + 1,6), 

+e^0« \N + 1, b)s\N -t- 1, a), + e*"^" |iV + 1, 6),|iV + 1, 6), + • • •] , (3) 
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where only terms that contribute to coincidence are shown. Thus, quantum interference is observed in the time 
slots from 2 to N, which we call "signal slots" hereafter. When 0^ = (pk-i, Alice and Bob's outcomes observed 
in the fcth signal slot are positively correlated. Anti-correlation is observed when ^fe — 4>k-i i tt. Thus, we can 
change the sign of the correlation for each time slot by modulating differential phase A(j)k = 4>k — (f'k-i by {0, tt} 
for each k. By contrast, the result of the coincidence in the 1st or {N + l)th slots is completely random. We 
call these slots "error slots". Alice and Bob do not observe any count in the (A^ + 2)th slot. As described in Sec. 
4, the {N + 2)th slot is used to detect cheating attempts by participants, so we call this slot a "detection slot" . 
Our QSS depends on the fact that the sign of the correlation in a signal slot is determined only by summarizing 
the outcomes of both Alice and Bob. 

Using this characteristic, we can realize a QSS with the following procedure. For simplicity, we do not 
consider the vacant slots. The procedure for detecting cheating using the count rate in the detection slots is 
described in Sec. 4. 

1. Charlie generates entangled photon pairs whose state is given by Eq. with (f)k modulated by {0,7r}. 
He separates signal and idler photons and sends them to Alice and Bob. 

2. Alice and Bob input the received photons into their interferometers, and detect the photons with photon 
counters connected to two output ports of the interferometers. Alice and Bob record the time instances 
in which they observed clicks, and which detectors clicked for each time instance. 

3. Alice and Bob inform Charlie of the time instances in which they observed clicks via classical communi- 
cation. They do not disclose the detectors that clicked. 

4. Charlie makes a key sequence using his modulation data in signal slots. Charlie encodes a message using 
this key and sends it to Alice and Bob. 

5. Charlie discloses the positions of the signal, error and detection slots to Alice and Bob. 

6. Alice and Bob discover the key only when they investigate the sign of the correlation in the signal slots 
by combining their information. 



We can generate the high-dimensional entangled state shown by Eq. ^ by using spontaneous parametric 
down-conversion (SPDC) jl5l [T^ or spontaneous four- wave mixing (SFWM) ^| ^1 ^1 1201 with a modulated 
pump. An example of such an entanglement source is shown in Fig. |21 in which SFWM is used to generate time- 
bin entangled photon pairs. A coherent pulse train from a pump pulse source is launched into a phase modulator, 
which modulates the phase of each pulse by {0, 7r/2}. Then on-off modulation is applied to the pulse train to 
insert two-sequential vacant slots randomly. Thus we can generate iV-sequential pump pulses with {0,7r/2} 
differential phase modulation, followed by two vacant slots. These pump pulses are input into a nonlinear 
medium, in which entangled photon pairs are generated through the SFWM process with a degenerated pump. 
The relationship between the phases of pump (j)p, signal 0s and idler 0.; is given by 



2(j)p = <j)s+ 0i- 



(4) 



With the above condition satisfied, and if we set the pump power relatively small so that the average number 
of photon pairs per slot becomes < 1, the obtained state can be approximated as a high-dimensional entangled 
photon pair whose relative phase is modulated by {0, tt} as in Eq. 

With these types of sources, the distribution of the number of photon pairs per packet becomes Poissonian. 
This implies that it is possible for two or more photons to be available in a packet, which opens the possibility 
for an eavesdropping strategy such as a BS attack. However, such an attack cannot be effective as long as the 
average number of photon pairs per pulse is sufhciently small, as we show in the next section. 
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Figure 2: High-dimensional time-bin entanglement source with relative-phase modulation. PM: phase modula- 
tor, IM: intensity modulator, NL: nonlinear medium for spontaneous four-wave mixing. 
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The previous QSS schemes based on entanglement use both the sign of correlation and the outcome of a 
phase-difference measurement of each photon (i.e. which detector clicked at the recipients' sites) |3 E]- In 
contrast, our scheme uses only the sign of correlation, which makes our approach much simpler than previous 
schemes. Moreover, recipients do not require equipment for selecting two non-orthogonal measurement bases as 
in 121 El • This is not a trivial issue in terms of implementation, because such equipment usually reduces the key 
distribution distance. For example, the use of active components such as a phase modulator for basis selection 
induces additional loss, which reduces the loss budget for transmission. Despite its simplicity, our scheme is 
secure against eavesdropping from outside and cheating attempts by one of the recipients, as described in the 
next two sections. 



3 Eavesdropping by outsider 

In this section we analyze the security of our QSS scheme against possible eavesdropping from outside the party. 
An eavesdropper (Eve) can undertake attacks that arc similar to those against QKD systems, such as an TR 
attack or a BS attack. In the following, we consider these two types of attack. 

3.1 I-R attack 

Eve captures both photons from Charlie and undertakes coincidence measurements using similar interferometers 
to those of Alice and Bob to obtain the relative phase A(/)fe = (f>k — 4>k~i- However, she can obtain only partial 
information about the relative phases of high-dimensional time-bin entangled states, because the average number 
of photon pairs per pulse is smaller than one. 

Then, at the time instances where Eve obtained A(/)fc, she prepares substitute photons in which the relative 
phase information that she obtained is encoded and sends them to Alice and Bob through lossless lines. Eve has 
two choices of substitute photons: entangled photon pairs or pairs of single photons with classical correlation. 

First, we consider the case in which Eve prepares entangled photon pairs. With her obtained relative phase 
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information A(^fc, she generates the following entangled photon pair, splits them into signal and idler, and sends 
one to Alice and the other to Bob. 

When the above photon pair passes the interferometers of Alice and Bob, whose function is given by Eq. jSJl, 
the state is converted into 

|*e) ^ ^{|fc-l,a),|fc-l,a), -|A:-l,a),|fc-l,6), 
-\k-l,b)s\k~l,a)^ + \k~l,b),\k-l,b), 
+ {l + e'^*'')\k,a)s\k,a), + (1 - e^^*'=)|A:, a),|fc, 6)^ 
+ {1 ~ e''^^'')\k,b)s\k,a), + (1 + e'^*'')\k,b)s\k,b), 
e''^'*"'\k + l,a)s\k + l,a), + e'^'>"'\k + l,a)s\k + l,b), 

W^'f"'\k + 1, b)s\k + 1, a), + e'^"^" \k + 1, b)s\k + 1, 5), + • • •} . (6) 

where only terms that contribute to coincidences are shown. The above equation indicates that Alice and Bob 
possibly observe coincidences in either of the k — 1, k, and (fc + l)th slots. If they observe coincidences in the 
fcth time slot, their measurement result correlates with Charlie's phase modulation data, which means that the 
eavesdropping is successful. However, when they observe a coincidence in the [k ± l)th slots, their outcomes 
are uncorrelated, so error occurs with a 50% probability. From the probability amplitude of Eq. ((HJ, an error 
occurs with 1/4 probability for a photon pair resent by Eve. 

Next, we consider the case in which Eve uses classical correlation. She prepares two single photons. Each 
photon is made into a 2-slot time-bin qubit whose relative phase is modulated based on the relative phase A(/)/j 
that she obtained in her measurement. The joint state of the two photons is expressed as 

|$c) = \{\k ~ 1)a + e'"^^" \k)A){\k - 1)b + e'^^" Ifc)^). (7) 

where 4'Ak — i'Bk when A0fe = and (j)Ak — 4'Bk + when A(j)k — tt. With this condition, Eve changes (l)Ak 
and 4>Bk randomly by {0,7r}. Eve inputs these two photons into Alice and Bob's interferometers. After these 
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photons pass through the interferometers, the whole state changes to 
|$c> ^ l{\k^l,a)A\k~l,a)B-\k-l,a}A\k-l,b)B 

o 

-\k ~ l,b)A\k - l,a)B + \k - l,b)A\k - l,b)B 

{1 + e''^^>'){l + e"^^'')\k,a)A\k,a)B + (1 + e^^-^^-)(l - e"^^')\k,a)A\k,b)B 

+ (1 _ e^^^^)(l + e"^^'')\k,b)A\k,a)B + (1 - e'*-^'=)(l - e"f'^'')\k,b) A\k,b) b 

gi(0Afc+</.sfc)|fc + 1, a)A\k + 1, a)B + e'('^'^'=+'^s'=)|fc + 1, a)A\k + 1, b) b 

+g»(0A.+0B.)|fc + 1^ + 1^ a)B + e*('^-^'=+^«'=)|fc + 1, b)A\k + 1, 6)b + • • •} , (8) 

where non-coincident terms are not shown for simphcity. When Ahce and Bob observe coincidences in the 
fcth time slot, the result is correlated to Charlie's modulation data as in the previous case, which means the 
eavesdropping is successful. However, the coincidences obtained in the (fc ± l)th slot induce errors with 50% 
probability. Using the probability amplitude of Eq. ©, the error probability is calculated to be 1/6. This 
means that using two single photons with classical correlation is the better strategy for Eve. In either case, the 
I-R attack by Eve can be detected by monitoring errors with some test bits. 

3.2 BS attack 

As stated in the previous section, if we use an entanglement source based on a parametric process pumped by 
a coherent source, the distribution of the number of photon pairs becomes Poissonian. This makes it possible 
for Eve to obtain information on the keys using a BS attack, without inducing errors. Here we show that a BS 
attack is ineffective against our scheme with a Poissonian photon-pair source, if the average number of photon 
pairs per slot is fewer than 1. 

We assume that the fiber transmittance between Charlie and Alice and that between Charlie and Bob are 
both a, and the average number of photon pairs per slot is fi. Eve replaces the fibers with her lossless lines. 
She then splits Charlie's signal and idler photon output into two paths with a beam splitter. Eve sends one 
beam with an average photon number of fia per pulse to both Alice and Bob through her lossless fiber so that 
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they do not notice any eavesdropping from changes in the count rates. Eve keeps the other beams of signal and 
idler photons with an average photon number of — a) in her quantum memory. Once Alice and Bob have 
disclosed the time instances in which they observed clicks, Eve puts her photons into interferometers that are 
identical to Alice and Bob's, and observes the coincidences, hoping that she obtains coincidences at the same 
time instances in which Alice and Bob observed coincidences. The probability of Eve obtaining a coincidence at 
a desired time instance is — a)^ PT, which is close to i/i when a is small. Therefore, in terms of the total 
sifted keys of Ugij bits. Eve has full information on at most ^^Ugif bits. This suggests that Eve can obtain only 
a fraction of the information if /i < 1, and so Alice, Bob and Charlie can ensure that Eve's mutual information 
is negligible by privacy amplification j22|. 

Thus, our QSS scheme is robust against attacks by an outside eavesdropper, even with a Poissonian photon- 
pair source. From the above arguments, it is clear that the robustness comes from the fact that Eve cannot 
reconstruct the whole wavefunction of a relative-phase modulated high-dimensional time-bin entanglement by 
an I-R attack or a BS attack. 

4 Dishonest Bob 

4.1 Bob's strategy 

In a QSS system, the sender of a secret key is a fair person as regards all recipients and does not have a preference 
for any individual, because dividing the secret key among the recipients is the purpose of the sender. Although 
an outside takeover of Charlie is a threat, this attack can be prevented by introducing an initial authentification 
procedure among the participants as in a QKD j23|. However, each recipient may, if he or she has a chance, take 
advantage of the others and try to obtain full information on the key by himself or herself. Therefore, preventing 
cheating attempts by recipients is an essential function for a QSS system. In the following, we assume that Bob 
is dishonest, and is trying to obtain full information on the key without being noticed by Alice and Charlie 
using an I-R-attack based strategy. 
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"Vacant slots" play a crucial role in the detection of dishonest Bob. First, we show that a cheating attempt 
by one of the recipients can constitute a very strong attack against a QSS protocol using {0, Trj-modulated 
high-dimensional entanglement without vacant slots. 

Bob intercepts both photons output by Charlie, and inserts them into his interferometers for coincidence 
measurement. As a result, he obtains partial information about the relative phases of the high-dimensional 
time-bin entanglement. Then, Bob prepares a time-bin qubit using his measurement data, which is expressed 
by 

|V) = ^(|fc-l)+e'*-|fc)), (9) 

where (j^Ak — ^(f'k — (f'B and (f>B is a value randomly chosen from {0,7r}. Bob sends the above state to Alice 
through a lossless line. The state is converted to the following state by Alice's interferometer. 

IV') ^ ^{|fc-l,a)-|fc-l,6) + (l + e"^^'=)|fc,a) + (l-e''^^'=)|fc,6) 

+e"l'^>'\k + l,a) +e"l'^>'\k + l,b)} (10) 

If Alice observes clicks in the fcth time slot, the result correlates with Bob and Charlie's, so Bob's attack is 
successful. On the other hand, her result is uncorrelated if the click occurs in the (fc±l)th slots. However, unlike 
an I-R attack by an outsider, Bob can declare clicks only at the time instances for which he has information, 
and so he can avoid inducing errors. As a result, Bob can obtain full information about the key without being 
noticed by Alice or Charlie. Thus, dishonest Bob can determine the time instances where coincidences occur, 
which makes cheating by a key recipient a serious threat to this protocol, if we do not introduce the vacant slots 
which we describe in the next section. 

4.2 Detection of dishonest Bob 

We consider a case in which Charlie sends states with vacant slots shown by Eq. As we have already 

stated, Alice observes no count in the detection slot if there is no eavesdropping and both Alice and Bob are 
honest. If dishonest Bob measures both photons using two interferometers, the state observed by Bob is shown 
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by Eq. 0. He observes coincidences in the error slot with a probabihty of 1/(2A^), and the results obtained in 
these coincidence events have no correlation with Charlie's modulation data. However, he cannot distinguish if 
a coincidence is obtained in signal or error slots, so he inevitably resends a substitute photon to Alice based on 
his measurement results, which are possibly uncorrelated to Charlie's data. Here, we assume that Bob observed 
a coincidence in the {N + l)th error slot. Then, Bob believes that he observed the state shown by 

i=(|7V),|7V), + e^^^=|iV+l),|iV+l)0, 

where Aipe is the "phase difference" observed in Bob's coincidence measurement and is actually a random value 
of {OjTt}. Consequently, Bob generates the following state and sends it to Alice. 

|^) = -i=(|iV)+e^*-|7V + l)) 

Here, (j>Ae — A0e — (j)Be and 4>Be is a value randomly chosen from {0, tt}. If this state passes through Alice's 
interferometer, the state is converted to 

IV') ^ ^{|iV,a)-|7V,fe) + (l + e*'^-^<=)|7V + l,a) + (l-e*^^=)|iV+l,6) 
2v 2 

+e»0Ae 1^ + 2, a) + e"''^' \N + 2, b)}. (11) 

This equation shows that Alice observes clicks in the detection slots with a probability of 1/4. Thus, counts in 
the detection slots imply cheating by the other participant, so Alice and Charlie stop the communication. 

Alice and Charlie also detect cheating by Bob if he resends a photon based on a coincidence measurement 
in the first slot. In this case, an erroneous count occurs in the detection slot of the previous packet. 

This detection method is based on the count rate measured by a single participant, not on the coincidence, 
which is why we can detect cheating by a participant who can determine the time instances of coincidence 
events. 

To reduce the probability of inducing counts in the detection slots. Bob can make an attack based on 
sequential coincidence events. If he observes n sequential coincidences, he resends a time-bin qubit spanned by 
n+1 slots to Alice. In this case too, there is a finite probability that Bob observes sequential coincidences that 



13 

include one in the first or the {N + l)th error slots as the first or last coincidences in the sequence, respectively. 
Here, we assume that Bob observed x sequential coincidences with the {N + l)th slot as the last event. Then, 
he considers that he observed the following entanglement. 

-yl= ( V e*"^"+i-'' \N + l-k)s\N + l- k), + e'^^\N + l),|iV + 1)^ ) 

0e is the "phase" that Bob thinks he observed in the coincidence in the {N + l)th error slot and that is actually 
a random value of {0,7r}. Therefore, he creates the following state and sends it to Alice. 



1 / " 

= y e*'^«+i-'= \N + l-k) + e 



r- . ^ .V . .^^1iV+l) . (12) 

Here, 4''^j^i_^. is the phase that correlates with Bob's measurement outcome in a signal slot. The above state 
is converted to the following state by Alice's interferometer. 

1 



2^/n+l 

n-2 



g»*>«+i-„ |7V + 1 - n, a) - e'-Piv+i-™ |iv + 1 - n, 6) 

^ |(e*'^Wi-n+fc +e'^W2-n+fc)|7V + 2-n + A;,a) 
+(e''^W+i-n+fe _ e'«^'iv+2-n+fc)|Ar + 2 - n + fc, 6)| 

+(e*0W + e*'^'=)|7V + 1, a) + (e*-^" - e*'^'=)|7V + 1, 6) 

+e''^«|7V + 2,a) + e''^«|7V + 2,6)] (13) 

Thus, Alice observes clicks in the detection slot with a probability of 2{n+i) ' ^° cheating by Bob is disclosed. A 
similar analysis can be undertaken for a case where Bob observes n sequential coincidences with the first slot 
of a packet as the first event of the sequential coincidences. 

4.3 Calculation 

If the detectors are ideal ones with no dark count, Alice and Charlie can always detect dishonest Bob by 
increasing the measurement time infinitely. However, in a realistic experimental situation, the ability to detect 
dishonest Bob is limited by the finite dark count rates of the detectors. In order to detect cheating, the count 
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rate in the detection slot should be larger than the dark count rate in the presence of dishonest Bob. Here, we 
estimate the maximum key distribution distance over which dishonest Bob is detectable, assuming realistic dark 
count rates, and assuming that Charlie is equipped with an entanglement source whose photon-pair number 
distribution is Poissonian. 

We consider the state after the interferometer given by Eq. © , and assume that the probability that a slot 
is a signal slot is 5, then the probabilities that a slot is an error slot, pe, or a detection slot, pd are expressed by 

Pd = IC^-S). (15) 

If we ignore the first and last slots of the whole session, the mark ratio (the probability that a slot is not a 
vacant slot) at the output of Charlie, M, is expressed as 

M = S+^^^{2S + 1). (16) 

When the transmittance between Charlie and Alice/Bob is a and the average number of photon pairs per pulse 
/i is small enough to allow us to disregard accidental coincidences, the shared key rate between Alice and Bob 
(= coincidence rate), Rk, is given by j21| . 

Rk = l^^Sa''. (17) 

Let us consider a case in which dishonest Bob resends a state based on a single coincidence event. The 
coincidence rate in a signal slot Rg and an error slot are expressed as Rg = ^/i and — jH, respectively 
pri . The coincidence rate per slot observed by dishonest Bob is given by 

Rcoin — RsS + RePe- (18) 

If the following condition is satisfied, Alice can detect dishonest Bob from the reduction in the count rate. 

R^orn < Mna (19) 

Here, a shows the transmittance between Alice and Charlie, including the quantum efficiencies of Alice's de- 
tectors. With Eqs. H16|l . (|18|l and (|19fl . the minimum transmittance for which Alice can detect dishonest Bob 
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from the count rate decrease is expressed as 

amin = 0.5. (20) 

Thus, if a is smaller than 0.5, it is impossible to construct a QSS system that is secure against dishonest Bob 
without employing the method described above. 

When a < amin. Bob randomly chooses Mfia events per slot from the coincidences he observes with a rate 
of Rcoin, creates substitute photons, and sends them to Alice. The probability that Bob happens to choose a 
coincidence in an error slot and resends a photon, y, is expressed by 

As we have already stated, when a resent photon is created based on the coincidence in an error slot, a photon is 
detected in a detection slot with a probability of 1 /4. Therefore, the count rate in a detection slot is expressed 
as 

Mfiay 
4 ■ 

If the dark count rate of Alice's detector is d, the following condition must be satisfied to detect cheating. 

(22) 

Thus, the threshold value of the transmittance above at which dishonest Bob can be detected is expressed as. 

= W^) ^''^ 

When a is smaller than both amin and ath, Alice cannot detect dishonest Bob. When we assume d = 10~^, 
fi = 0.1 and S = 0.5, ath — —26 dB gives the minimum transmittance with which detect dishonest Bob is 
detectable. 

If Bob observes sequential coincidences and rcscnds a state that is constructed using his measurement results, 
he may be able to reduce the probability of causing erroneous counts in the detection slots. So, we now consider 
a case in which Bob resends a state spanned by n + 1 slots only when he observes n sequential coincidence 
counts. 
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We assume that the total number of slots in the whole session is Naii- When the packet dimensions are 
larger than n and the probability of observing a coincidence in a signal slot Rs is small, Ng , the total number 
of n sequential coincidences in signal slots in the whole session is approximated by 

N,^R^SNau = ^Nau. (24) 

Similarly, N^, namely the total number of n sequential coincidences, which includes n — 1 signal slots and a 
error slot as the first or last event, is approximated by 

Ne ~ ReR'r'peNall = f^^^a/i- (25) 

Then, n-sequential coincidence rate observed by dishonest Bob, which is defined as the number of n-sequential 
coincidences normalized by the number of slots in the whole session, is expressed as 

Rcoin = — -77 — R"S + ReRg ^Pe (26) 

As in the single coincidence case. Bob should satisfy the condition expressed by Eq. H19|l . so as not to be 
detected by the reduction in the count rate at Alice's site. Using Eq. H26() . the minimum transmittance that 
violates this condition, amin is given by 

armn = (27) 

If the transmittance is smaller than Bob can disguise Alice's count rate by using resent states generated 

using n-sequential coincidence counts. 

When a < amin is satisfied. Bob randomly chooses n-sequential events from all the coincidence events, 
constructs the states using those events, and sends them to Alice. Here, he has to keep Alice's count rate at 
Af/ia. The probability that Bob happens to choose an n sequential coincidence that includes an error slot is 
the same as Eq. (|21() . When Bob sends a state that is constructed using an n sequential coincidence with an 
error slot, the probability that Alice detects a photon in a detection slot is given by 2{n+i) ■ order to detect 
dishonest Bob, the count rate at the detection slot should be larger than the dark count rate. This condition is 
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expressed as 

M^ay 



> d. (28) 



2(n+l) 

Using the above equation, the threshold value of the transmittance at which Alice can detect dishonest Bob is 
given by 

^din + 1) 

- (29) 

The circles in Fig. Oshow athn for each n. Here, S*, ji and d are assumed to be 0.5, 0.1 and 10^^, respectively. 
The transmittance threshold given by Eq. (|27|l is shown with squares in Fig. |21 If the transmittance is below 
both curves, Bob can cheat Alice. With the above parameter values, a sequential attack with n ~ 2 gives the 
minimum transmittance for security, ~ — 24 dB. When the detector quantum efficiency and out-coupling loss 
of the entanglement source are 10% and 4 dB, respectively, the maximum transmission loss between Charlie 
and Alice/Bob is 10 dB. This means that a secure QSS system can be constructed over 100 km (50 km x 2) of 
optical fiber with a loss of 0.2 dB/km. 

This scheme uses the count rate in the detection slots to detect cheating by the key recipients. This 
cheat-detection method is uncommon in most of the conventional QKD or QSS systems, in which error rate 
monitoring is the way to detect eavesdropping and cheating. Therefore, a more detailed security analysis, 
including the derivation of the privacy amplification factor that takes account of this cheat-detection method, 
is very important in terms of evaluating the performance of a QSS system based on the proposed scheme. 



5 Discussion 

5.1 Analogy with differential phase shift QKD 

In previously reported QSS schemes using two-photon entanglement , entanglement sources generate four 
non-orthogonal Bell states and the recipients use two non-orthogonal measurement bases. Therefore, these 
schemes can be considered to be two-photon versions of BB84 QKD In contrast, our proposed scheme can 
be regarded as a two-photon version of differential-phase-shift (DPS) QKD [23 EE!- ^ DPS-QKD system. 



18 




2 3 4 

Number of sequential clicks 



Figure 3: Threshold transmittance as a function of the number of sequential coincidences n. Squares show the 
transmittance given by Eq. (|27(l . while circles show the boundary given by Eq. H29(l . When the transmittance 
is smaller than both of these values, dishonest Bob can deceive Alice without being noticed. 

Alice randomly modulates the phase of a weak coherent pulse train by {0, tt} for each pulse, and sends it to 
Bob with an average photon number of < 1 . The state sent by Alice is expressed as 



1 ^ 



(30) 

where, (j)k = {0,7r}. Bob measures the phase difference of each consecutive pulse, Aiph = (j^k-i — (f>k, using 
second-order interferometry obtained with a 1-bit delay interferometer. The security of the DPS-QKD is based 
on the fact that Eve can obtain only partial information on the relative phases in Eq. H30I) . On the other 
hand, the QSS scheme measures the relative phase of each consecutive product state shown in Eq. |^ using 
fourth-order interferometry. Thus, we can expand the concept of DPS-QKD to two-photon states and construct 
a simpler QSS system that requires only two-value phase modulation. 
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5.2 Modified scheme 

The essential point as regards detecting dishonest Bob is that the two recipients do not have the information on 
the time instances of the error slots. Therefore, the same function can be implemented by randomly changing 
the time intervals of the packets, while fixing the dimension of the packets. In this case, we use the same 
state as Eq. with a fixed N, and insert random numbers of vacant time slots between packets. Then, the 
theory described above can be applied to this modified scheme. However, the scheme with randomized packet 
dimensions obviously utilizes time slots efficiency, so a larger key rate is expected. 

6 Conclusion 

We have proposed a new QSS scheme based on time-bin entanglement whose relative phases and dimension 
are modulated. A sender can change the signs of correlation of the two recipients by modulating the relative 
phase with {0, tt}, which can be used as a shared key. This protocol is secure against an I-R attack and a 
BS attack from outside because of the non-orthogonality of the high-dimensional time-bin entanglement. A 
cheating attempt based on an I-R attack by one of the recipients can be detected by randomly changing the 
dimension of entanglement and inserting two vacant slots between each packet of entangled states. Because 
recipients cannot know the time instances of the error slots, cheating by a recipient induces an erroneous count 
in a detection slot, by which the other recipient can detect the existence of cheating. We analyzed the security 
of the proposed protocol based on specific attacks, and so an unconditional security analysis is an important 
future consideration. This scheme does not require a three-particle entangled state or basis selection mechanism 
at a recipients' site, and thus has better experimental feasibility. 

This work was supported in part by National Institute of Information and Communications Technology 
(NICT) of Japan. 
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